<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
+1<br>
<br>
<div class="moz-cite-prefix">On 08/15/2018 01:10 PM, David Davis
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAHa=2W=PJ_j3J-ZBKHrUd3at8krFjaqZ+hyJgMRUpdkyOSVhHA@mail.gmail.com">
<div dir="ltr">Thanks everyone for the feedback. I have opened a
PR for PUP-7 which (if approved) will require 2FA for the Pulp
organization in Github:
<div><br>
</div>
<div><a href="https://github.com/pulp/pups/pull/14"
target="_blank" moz-do-not-send="true">https://github.com/pulp/pups/pull/14</a></div>
<div><br>
</div>
<div>Feedback welcome. Also, I'd like to call for a vote by
August 27, 2018. Per PUP-1[0], are the voting options:</div>
<div><br>
</div>
<div>
<div>+1: "Will benefit the project and should definitely be
adopted."</div>
<div>+0: "Might benefit the project and is acceptable."</div>
<div>-0: "Might not be the right choice but is acceptable."</div>
<div>-1: "I have serious reservations that need to be thought
through and addressed."</div>
<div><br>
</div>
<div>[0] <a
href="https://github.com/pulp/pups/blob/master/pup-0001.md"
target="_blank" moz-do-not-send="true">https://github.com/pulp/pups/blob/master/pup-0001.md</a></div>
<div>
<div dir="ltr" class="m_1814242313330830155gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div><br>
</div>
<div>David<br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr">On Wed, Aug 1, 2018 at 3:00 PM David Davis <<a
href="mailto:daviddavis@redhat.com" target="_blank"
moz-do-not-send="true">daviddavis@redhat.com</a>> wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">+1 to opening a PUP. Seems like that’s the best
way to document the policy. I will start working on this.<br
clear="all">
<div>
<div dir="ltr"
class="m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772gmail_signature"
data-smartmail="gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div><br>
</div>
<div>David<br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr">On Mon, Jul 30, 2018 at 2:21 PM Brian
Bouterse <<a href="mailto:bbouters@redhat.com"
target="_blank" moz-do-not-send="true">bbouters@redhat.com</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">
<div>+1 to requiring it. I also already have it enabled.
Would it be possible to either (a) turn this into a
short pup and call for a vote or (b) add a date to
close this email thread decision by?</div>
<div><br>
</div>
<div>Let me know if I should help write/review any.<br>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Sat, Jul 28, 2018 at 6:09
AM, Tatiana Tereshchenko <span dir="ltr"><<a
href="mailto:ttereshc@redhat.com" target="_blank"
moz-do-not-send="true">ttereshc@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">+1, enabled.<br>
</div>
<div
class="m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712HOEnZb">
<div
class="m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712h5">
<div class="gmail_extra"><br>
<div class="gmail_quote">On Fri, Jul 27, 2018
at 12:02 AM, Dennis Kliban <span dir="ltr"><<a
href="mailto:dkliban@redhat.com"
target="_blank" moz-do-not-send="true">dkliban@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote"
style="margin:0 0 0 .8ex;border-left:1px
#ccc solid;padding-left:1ex">
<div dir="ltr">+1, but I already have it
enabled. <br>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Thu, Jul 26,
2018 at 3:53 PM, David Davis <span
dir="ltr"><<a
href="mailto:daviddavis@redhat.com"
target="_blank"
moz-do-not-send="true">daviddavis@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote"
style="margin:0 0 0
.8ex;border-left:1px #ccc
solid;padding-left:1ex">
<div dir="ltr">I got a notification
from another organization I am a
member of on Github[0] that they
are going to require Two Factor
Authentication[1] in response to
recent news about some malicious
code being shipped in a
compromised npm package[2].
<div><br>
</div>
<div>We are vulnerable to having
malicious code deployed to PyPI
if one of our Github accounts is
compromised. Thus, I wonder if
we should also require that
people with a commit bit have
Two Factor Authentication
enabled.
<div><br>
</div>
<div>Thoughts?<br>
<div><br>
</div>
<div>[0] <a
href="https://community.theforeman.org/t/require-2fa-for-github-organization-members/10404"
target="_blank"
moz-do-not-send="true">https://community.theforeman.org/t/require-2fa-for-github-organization-members/10404</a><br
clear="all">
<div>
<div dir="ltr"
class="m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712m_5646608958576497197m_5807261843911257054m_-8136455174575536232gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div>[1] <a
href="https://help.github.com/articles/requiring-two-factor-authentication-in-your-organization/"
target="_blank" moz-do-not-send="true">https://help.github.com/articles/requiring-two-factor-authentication-in-your-organization/</a></div>
<div>[2] <a
href="https://www.theregister.co.uk/2018/07/12/npm_eslint/"
target="_blank" moz-do-not-send="true">https://www.theregister.co.uk/2018/07/12/npm_eslint/</a></div>
<span
class="m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712m_5646608958576497197m_5807261843911257054HOEnZb"><font
color="#888888">
<div><br>
</div>
<div>David<br>
</div>
</font></span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com"
target="_blank"
moz-do-not-send="true">Pulp-dev@redhat.com</a><br>
<a
href="https://www.redhat.com/mailman/listinfo/pulp-dev"
rel="noreferrer" target="_blank"
moz-do-not-send="true">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
<br>
</blockquote>
</div>
<br>
</div>
<br>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com"
target="_blank" moz-do-not-send="true">Pulp-dev@redhat.com</a><br>
<a
href="https://www.redhat.com/mailman/listinfo/pulp-dev"
rel="noreferrer" target="_blank"
moz-do-not-send="true">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
<br>
</blockquote>
</div>
<br>
</div>
</div>
</div>
<br>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com" target="_blank"
moz-do-not-send="true">Pulp-dev@redhat.com</a><br>
<a
href="https://www.redhat.com/mailman/listinfo/pulp-dev"
rel="noreferrer" target="_blank"
moz-do-not-send="true">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
<br>
</blockquote>
</div>
<br>
</div>
</blockquote>
</div>
</blockquote>
</div>
<!--'"--><br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Pulp-dev mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Pulp-dev@redhat.com">Pulp-dev@redhat.com</a>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/pulp-dev">https://www.redhat.com/mailman/listinfo/pulp-dev</a>
</pre>
</blockquote>
<br>
</body>
</html>